# viem@2.41.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:47.000Z
- Files reviewed: 3710
- Findings: 22 medium, 28 low severity findings
- Report: https://security.togoder.click/npm/viem@2.41.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package viem@2.41.2 on Oct 4, 2026. An AI review of 3710 source files produced 22 medium, 28 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] External network request with user-controlled URLs

Finding ID: `NPS-68E0F786B591`

File: `_cjs/utils/ccip.js:78`

The ccipRequest function performs HTTP requests to arbitrary URLs provided by on-chain contract data via the OffchainLookup mechanism. While this is the intended EIP-3668 CCIP-read behavior, the URLs are fully attacker-controllable if a malicious contract is interacted with, allowing potential SSRF or data exfiltration to attacker-controlled endpoints. The fetched URLs are constructed by replacing '{sender}' and '{data}' placeholders in the URL string, and the response is parsed and returned as call data.

### [medium] Potential SSRF via dynamic URL interpolation

Finding ID: `NPS-6A7B144C46CD`

File: `_cjs/utils/ccip.js:83`

The code dynamically builds URLs by replacing placeholders with sender address and calldata, then fetches them. There is no allowlist or validation of the destination host, so a malicious contract could direct requests to internal network resources or arbitrary external services.

### [medium] Resource exhaustion / unbounded recursion

Finding ID: `NPS-4624D8B9DC66`

File: `_cjs/utils/encoding/fromRlp.js:20`

The fromRlp function creates a cursor with recursiveReadLimit set to Number.POSITIVE_INFINITY, disabling the library's built-in protection against deeply nested RLP structures. Combined with recursive list parsing in readList/fromRlpCursor, a maliciously crafted deeply-nested RLP payload could cause stack exhaustion (RangeError: Maximum call stack size exceeded) or excessive memory consumption, resulting in a denial-of-service condition for callers that process untrusted RLP data.

### [medium] Unvalidated network requests (SSRF potential)

Finding ID: `NPS-EFD5B1C020E3`

File: `_cjs/utils/ens/avatar/utils.js:27`

The functions isImageUri, getMetadataAvatarUri, and parseAvatarUri perform fetch() requests to URLs derived from the input 'uri' parameter without validating or restricting the target host. An attacker controlling the URI could cause the library to request arbitrary internal or external services, potentially leading to SSRF or information disclosure.

### [medium] Potential XSS via SVG data URI injection

Finding ID: `NPS-8F73E58F37B1`

File: `_cjs/utils/ens/avatar/utils.js:113`

In resolveAvatarUri, when parsedUri starts with '<svg', it is base64-encoded and prefixed with 'data:image/svg+xml;base64,'. This URI is later returned and potentially rendered by consumers. SVG can contain scripts; if the consumer renders this data URI as an image in an insecure context, it may lead to XSS. The code does not sanitize SVG content.

### [medium] Potential message boundary / protocol confusion in extractMessages

Finding ID: `NPS-9AD99A932848`

File: `_cjs/utils/rpc/ipc.js:8`

extractMessages tracks only brace nesting and ignores string literals and escapes. JSON strings containing unmatched braces (e.g. '{"a":"}"}') will corrupt the nesting level, causing incorrect message splitting, dropped messages, or merged payloads. Depending on the caller, this can be used to smuggle or truncate messages across the IPC boundary.

### [medium] Unvalidated filesystem path passed to net.connect

Finding ID: `NPS-B54831844B0C`

File: `_cjs/utils/rpc/ipc.js:33`

getIpcRpcClient(path) forwards the caller-supplied path directly to node:net connect() as an IPC endpoint with no normalization, allowlisting, or scope restriction. If path is influenced by untrusted input, it could connect to arbitrary local sockets (e.g. privileged daemons) rather than an intended package-scoped endpoint.

### [medium] Unbounded JSON parsing from untrusted socket input

Finding ID: `NPS-8F25A79D3461`

File: `_cjs/utils/rpc/ipc.js:50`

The onData handler parses every complete JSON message received over the IPC socket with JSON.parse(). There is no validation, size limit, or schema check before parsing. A malicious or compromised peer can send arbitrarily large or deeply nested JSON, causing high CPU/memory usage (JSON bombs / DoS). The parsed object is then passed directly to onResponse().

### [medium] Sensitive data handling

Finding ID: `NPS-E2C6D874196C`

File: `_cjs/zksync/accounts/toMultisigSmartAccount.js:8`

The function receives private keys as parameters and uses them to sign hashes. While this is expected behavior for a multisig smart account utility, handling private keys in memory and passing them to a signing function introduces risk if the keys are logged, stored, or transmitted improperly. The code does not appear to exfiltrate keys, but the pattern warrants caution since private keys are highly sensitive credentials.

### [medium] Potential for malicious factory

Finding ID: `NPS-C0DB61B9C9EF`

File: `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js:29`

The factoryAddress is configurable by the caller (parameters.factoryAddress) and defaults to a hardcoded address. If a malicious factory is provided, it could deploy a backdoored smart account or perform arbitrary calls during account creation. This is a design risk inherent in account abstraction but should be clearly documented.

### [medium] Hardcoded factory address

Finding ID: `NPS-0D939F4D733A`

File: `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js:30`

A default factory address '0x5d82735936c6Cd5DE57cC3c1A799f6B2E6F933Df' is hardcoded instead of being derived from the provided entryPoint. This could lead to unexpected account creation address if the factory is not intended for the given chain/entryPoint, potentially causing loss of funds or incorrect account deployment.

### [medium] Owner parsing without validation

Finding ID: `NPS-122E16E38E49`

File: `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js:34`

The owner account is parsed via parseAccount(parameters.owner) without verifying that it is a valid EOA or that the address matches the expected owner. If an attacker can influence the owner parameter, they could set themselves as owner and drain funds.

### [medium] Potential denial of service via unbounded recursion

Finding ID: `NPS-7256C45E9EE3`

File: `_esm/utils/encoding/fromRlp.js:18`

The createCursor call sets recursiveReadLimit to Number.POSITIVE_INFINITY, disabling the library's built-in recursion limit. A deeply nested or maliciously crafted RLP input can cause unbounded recursion in readList/fromRlpCursor, leading to a stack overflow and process crash (DoS).

### [medium] User-controlled network requests

Finding ID: `NPS-93BF50130DBD`

File: `_esm/utils/ens/avatar/utils.js:13`

The functions isImageUri, getMetadataAvatarUri, and parseAvatarUri perform fetch() requests to URIs derived from user/on-chain input (ENS avatar records). While intended for avatar resolution, these requests can reach arbitrary external endpoints, enabling SSRF-style behavior or privacy leakage (IP/user-agent disclosure) when untrusted ENS records are resolved.

### [medium] Unvalidated URL fetching

Finding ID: `NPS-83CB6724B928`

File: `utils/ccip.ts:138`

The ccipRequest function performs fetch() requests to URLs supplied by on-chain contract data (the 'urls' array from the OffchainLookup error). While this is the intended EIP-3668 (CCIP Read) behavior, it allows arbitrary external HTTP requests with attacker-controllable URLs, which could be leveraged for SSRF-like scenarios depending on the caller's environment.

### [medium] No allowlist/scheme validation on outbound requests

Finding ID: `NPS-5A0D552C7727`

File: `utils/ccip.ts:138`

URLs are used directly in fetch() without checking scheme (http/https) or host allowlisting, and template substitution replaces '{sender}' and '{data}' without encoding. A malicious contract could redirect requests to internal endpoints or exfiltrate calldata to unintended hosts.

### [medium] Unvalidated network fetch with user-controlled URI

Finding ID: `NPS-6E66C44DAB55`

File: `utils/ens/avatar/utils.ts:47`

isImageUri and getMetadataAvatarUri call fetch() with URIs derived from ENS avatar metadata (which can be attacker-controlled via ENS records). This enables SSRF-style requests to internal or arbitrary hosts, and the HEAD/GET responses are used to infer content. In browser contexts this is somewhat constrained by CORS, but in Node/backend contexts (e.g., server-side usage) it can reach internal services.

### [medium] HTML/SVG data URI construction

Finding ID: `NPS-63D33F694795`

File: `utils/ens/avatar/utils.ts:158`

resolveAvatarUri base64-encodes raw input when it starts with '<svg', producing a data:image/svg+xml URI. This is a known XSS vector if the resulting URI is later rendered as HTML rather than as an image (SVG can contain scripts). The library returns the URI to the caller, so impact depends on consumer handling.

### [medium] Mutable global fetch override

Finding ID: `NPS-410771EADD78`

File: `utils/rpc/http.ts:88`

`fetchFn` can be provided via options or params, silently replacing the global fetch function. A malicious dependency could supply a fetchFn that exfiltrates all RPC request bodies (including signed transactions or auth tokens) to a third party.

### [medium] Potential credential leakage via custom headers

Finding ID: `NPS-09ECA4317FFD`

File: `utils/rpc/http.ts:132`

User-supplied `headers` from `fetchOptions` are merged after default Content-Type, and there is no validation restricting headers. Combined with the URL override, this could allow authentication headers intended for one host to be sent to an attacker-controlled host.

### [medium] SSRF risk via onRequest callback

Finding ID: `NPS-C334CBCFBBE5`

File: `utils/rpc/http.ts:143`

The `onRequest` callback receives the Request and init object and can return an arbitrary `url` that overrides the original URL (`args.url ?? url`). If this callback is attacker-influenced, it enables Server-Side Request Forgery by redirecting requests to arbitrary internal or external endpoints.

### [medium] Weak Randomness for Identifier Generation

Finding ID: `NPS-D5A6EFB6168C`

File: `utils/uid.ts:10`

The uid() function uses Math.random() to generate identifiers. Math.random() is not cryptographically secure and is predictable, which is unsuitable for security-sensitive uses such as tokens, session IDs, CSRF nonces, or password reset links. If this utility is used for such purposes, it could allow attackers to predict or brute-force generated values. This is a code-quality/security weakness rather than an active malicious pattern.

### [low] dynamic property access with user input

Finding ID: `NPS-C8CDBB7DBAB2`

File: `_cjs/actions/getContract.js`

Uses Proxy objects to dynamically resolve function/event names from ABI onto contract methods; this is a legitimate pattern for building a contract interface, not obfuscation or dynamic code execution.

### [low] top-level module side effects

Finding ID: `NPS-DDCF0A001259`

File: `_cjs/actions/getContract.js`

Module exports functions but does not execute network, file system, or process operations at import time. All behavior is invoked only when consumers call getContract and execute returned methods.

### [low] configuration

Finding ID: `NPS-18D6AB02E283`

File: `_cjs/chains/definitions/zetachain.js`

This file is a standard chain definition for ZetaChain (viem/chain definitions). It contains only static configuration data: chain ID, name, native currency, RPC URL, multicall contract address, and block explorer URL. No execution of external code, no environment variable harvesting, no obfuscation, no network requests performed at import time, no file system manipulation, and no process spawning. The RPC URL is a legitimate public endpoint. Safe to use.

### [low] Response used as calldata without origin validation

Finding ID: `NPS-6037EB5D3259`

File: `_cjs/utils/ccip.js:100`

The HTTP response body from the external URL is treated as hex calldata and passed back into an on-chain call. While isHex validation exists, there is no cryptographic verification of the response, which is inherent to the CCIP-read standard but could be abused if the underlying contract does not verify signatures.

### [low] Missing input bound validation

Finding ID: `NPS-B6020FCB1A3A`

File: `_cjs/utils/encoding/fromRlp.js:53`

readLength trusts the encoded length bytes (readUint8/16/24/32) and passes them to cursor.readBytes / list iteration without clamping against remaining buffer size. While cursor.readBytes may throw on out-of-bounds, the use of readUint32 and the absence of a maximum-length guard can facilitate memory/CPU exhaustion attacks when parsing untrusted input.

### [low] Regex complexity / ReDoS potential

Finding ID: `NPS-57ED830F91AA`

File: `_cjs/utils/ens/avatar/utils.js:10`

The regexes networkRegex and ipfsHashRegex are applied to untrusted input without timeout controls. While not obviously catastrophic, they contain nested quantifiers and alternations that could cause performance degradation on crafted inputs.

### [low] Unbounded fetch of arbitrary JSON metadata

Finding ID: `NPS-9D0CEAC3143C`

File: `_cjs/utils/ens/avatar/utils.js:137`

getMetadataAvatarUri fetches a URI and parses the response as JSON without limits on size or content type. A malicious metadata endpoint could return a very large payload causing memory exhaustion, or a specially crafted JSON that leads to unexpected behavior in getJsonImage.

### [low] Trusted Setup File Loading

Finding ID: `NPS-755FBAB9CA91`

File: `_cjs/utils/kzg/setupKzg.js:6`

The function loads a trusted setup from a file path provided as an argument. Depending on how this function is called, an attacker-controlled path could lead to reading arbitrary files. However, this is a standard pattern for KZG libraries and is not inherently malicious.

### [low] Unhandled exceptions in socket data handler

Finding ID: `NPS-7461616AD45A`

File: `_cjs/utils/rpc/ipc.js:50`

JSON.parse() inside onData is not wrapped in try/catch. A malformed frame throws synchronously from the socket 'data' event, which can crash the process or leave the RPC client in an inconsistent state (message corruption after partial parsing).

### [low] weak randomness

Finding ID: `NPS-AC156082C37F`

File: `_cjs/utils/uid.js:12`

The uid function uses Math.random() for generating identifiers, which is not cryptographically secure. If these IDs are used for security-sensitive purposes (e.g., session tokens, password reset tokens), they could be predictable. However, this is a common pattern for non-security-related unique IDs and does not indicate malicious intent.

### [low] Stub signature hardcoded

Finding ID: `NPS-A0639238031F`

File: `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js:95`

The getStubSignature method returns a fixed 65-byte signature (0xffff...1c) that is not derived from any input. This is typically used for gas estimation, but a static stub can be misused for replay attacks if not properly validated by the EntryPoint. However, this is standard practice in ERC-4337 account abstractions.

### [low] Network request

Finding ID: `NPS-9B0C6558A6D8`

File: `_esm/actions/public/call.js:130`

The code makes JSON-RPC calls via client.request (eth_call) to Ethereum nodes. This is expected behavior for a blockchain client library and not suspicious exfiltration.

### [low] Dynamic import

Finding ID: `NPS-F9F11CEEA31A`

File: `_esm/actions/public/call.js:138`

Dynamic import of '../../utils/ccip.js' is used for lazy-loading CCIP-Read functionality. This is a controlled internal path, not influenced by external input, and appears to be part of the viem Ethereum library's normal operation.

### [low] External network requests

Finding ID: `NPS-33C7D9DC5794`

File: `_esm/utils/ens/avatar/parseAvatarRecord.js`

The function ultimately resolves and returns a URI (via getMetadataAvatarUri or parseAvatarUri) that may point to external gateways (gatewayUrls). This is expected behavior for an avatar resolver but could be used for tracking or fetching malicious content if the URI is attacker-controlled. No direct exfiltration of sensitive data is present.

### [low] Potential data URI parsing with atob

Finding ID: `NPS-BD6F3251F8DF`

File: `_esm/utils/ens/avatar/parseAvatarRecord.js:33`

The code decodes a base64-encoded data URI using atob() and then parses it as JSON. While not malicious by itself, this could allow for injection of arbitrary JSON data if the source (NFT tokenURI) is attacker-controlled, potentially leading to denial of service or unexpected behavior, though not direct code execution.

### [low] Image element loads arbitrary URI

Finding ID: `NPS-AE956C974AF4`

File: `_esm/utils/ens/avatar/utils.js:33`

In the CORS fallback path, an <img> element is created with src set to the untrusted uri without scheme validation. This can trigger requests to arbitrary external hosts and enable tracking of the resolving client.

### [low] Fetches and parses remote JSON metadata

Finding ID: `NPS-21CB44253AAA`

File: `_esm/utils/ens/avatar/utils.js:123`

getMetadataAvatarUri fetches arbitrary URI and calls .json() on the response, then feeds the result into parseAvatarUri. Resolution of attacker-controlled ENS metadata can drive further outbound requests and potentially large/embedded payloads (e.g., data URIs) to be processed.

### [low] Dynamic import

Finding ID: `NPS-E435502FE61B`

File: `_esm/utils/rpc/webSocket.js:7`

The code dynamically imports the 'isows' package to obtain a WebSocket implementation. This is a standard pattern for cross-environment compatibility and the module name is hardcoded, not computed from external input.

### [low] Potential smart contract function name mismatch

Finding ID: `NPS-D3316B007D8A`

File: `_esm/zksync/actions/finalizeWithdrawal.js:79`

The ABI encodes a function named 'finalizeDeposit' with a parameter named '_finalizeWithdrawalParams', but the function is intended to finalize a withdrawal. While this is likely a naming artifact in the SDK and not malicious, the mismatch could theoretically lead to incorrect contract interaction if the ABI does not match the actual on-chain contract. However, no malicious intent is evident.

### [low] Dynamic behavior based on remote input

Finding ID: `NPS-8BBDAF7E9A92`

File: `utils/ccip.ts:129`

Method selection (GET/POST) depends on substring presence ('{data}') in a remote-controlled URL, and JSON/text parsing branches on server-provided Content-Type. Behavior is driven by untrusted on-chain/external data.

### [low] Weak regex-based URI classification

Finding ID: `NPS-0900A61724BE`

File: `utils/ens/avatar/utils.ts:36`

The networkRegex, ipfsHashRegex, base64Regex, and dataURIRegex are permissive and may misclassify crafted strings (e.g., unusual schemes or encodings), potentially leading to unexpected gateway resolution or data URI handling. Not directly malicious but can be a source of bypasses.

### [low] Gateway URL replacement without strict validation

Finding ID: `NPS-BC5A54ADF718`

File: `utils/ens/avatar/utils.ts:120`

resolveAvatarUri replaces arweave.net URLs with a caller-provided gatewayUrls.arweave value. If gatewayUrls is influenced by untrusted input, avatars could be redirected to arbitrary hosts. The custom gateway is only trimmed of a trailing slash, not validated as an http(s) origin.

### [low] Unsafe content-type based parsing / loose error handling

Finding ID: `NPS-75EF7ADEDD8F`

File: `utils/rpc/http.ts:163`

Response is parsed as JSON based on a substring content-type check and falls back to JSON.parse of arbitrary text. While not inherently malicious, this broadens parsing surface and could facilitate prototype-pollution style payloads if callers misuse the returned data.

### [low] Dynamic Import

Finding ID: `NPS-CF957AFB3DAD`

File: `utils/rpc/webSocket.ts:26`

The code uses `await import('isows')` to dynamically load the WebSocket implementation. This is a legitimate use for a WebSocket RPC client and not obfuscation or malicious dynamic loading.

### [low] Network Request

Finding ID: `NPS-36EE27323EBC`

File: `utils/rpc/webSocket.ts:27`

The code establishes WebSocket connections to a user-provided URL for RPC communication. This is the intended functionality of the library and not suspicious.

### [low] Cryptographic operation

Finding ID: `NPS-884A12E4103A`

File: `utils/signature/recoverPublicKey.ts`

Implements public key recovery from ECDSA signatures using secp256k1. This is standard cryptographic functionality (e.g., for Ethereum signature verification), not wallet draining. No private keys or seed phrases are accessed.

### [low] Dynamic import

Finding ID: `NPS-F388D052AADF`

File: `utils/signature/recoverPublicKey.ts:30`

Uses dynamic import() to load '@noble/curves/secp256k1' at runtime. This appears to be a legitimate cryptographic library import for lazy loading, not obfuscation or external code loading. No user-controlled input is used in the import path.

### [low] Deprecated API usage

Finding ID: `NPS-9808D1601FCE`

File: `zksync/actions/getAllBalances.ts:29`

The function calls 'zks_getAllAccountBalances', which is marked as deprecated and removed from the node API. This may cause runtime failures but is not a security vulnerability.

## Files reviewed

- `_cjs/utils/ccip.js` (medium): This is legitimate CCIP-read (EIP-3668) functionality but performs network requests to attacker-controllable URLs derived from on-chain data, posing potential SSRF and data exfiltration risks inherent to the protocol.
- `_cjs/utils/encoding/fromRlp.js` (medium): The file contains no malicious patterns (no exfiltration, credential harvesting, code execution, or network/file/process access), but it disables recursion limits and lacks length bounds, creating a potential denial-of-service risk when parsing untrusted RLP input.
- `_cjs/utils/ens/avatar/utils.js` (medium): The code performs network requests based on untrusted URIs and processes SVG data without sanitization, presenting SSRF and potential XSS risks, but no direct malicious patterns such as exfiltration, credential harvesting, or code execution were found.
- `_cjs/utils/rpc/ipc.js` (medium): The IPC RPC client contains no exfiltration, credential harvesting, obfuscation, mining, backdoor, or process-spawning code, but it parses untrusted socket data with unbounded JSON.parse, has a brace-counting parser that mishandles JSON strings, and forwards an unvalidated path to net.connect, creating DoS and potential local-socket-abuse risks.
- `_cjs/zksync/accounts/toMultisigSmartAccount.js` (medium): The code implements multisig signing with private keys as expected, but handling private keys in a third-party package poses a medium risk if the package is compromised or keys are mishandled.
- `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js` (medium): The code is part of a legitimate smart account implementation but contains several design risks such as hardcoded factory address, stub signature, and configurable factory that could lead to fund loss if parameters are not trusted.
- `_esm/utils/encoding/fromRlp.js` (medium): The RLP decoding logic appears functionally benign with no exfiltration, credential harvesting, or code execution patterns, but explicitly disables the recursive read limit, exposing consumers to stack-overflow denial-of-service on untrusted input.
- `_esm/utils/ens/avatar/parseAvatarRecord.js` (medium): The code is a legitimate ENS avatar parser with no clear malicious patterns, but it processes external URIs and decodes base64 JSON, which pose minor risks if inputs are untrusted.
- `_esm/utils/ens/avatar/utils.js` (medium): Code performs user/on-chain-controlled outbound HTTP requests and image loads for ENS avatar resolution, which could be abused for SSRF/tracking but contains no exfiltration, credential harvesting, obfuscation, or code execution backdoors.
- `utils/ccip.ts` (medium): This is a legitimate viem CCIP-Read implementation, but it performs unvalidated outbound HTTP fetches to URLs supplied by external contract data, warranting caution though no clear malicious patterns (exfiltration, credential harvesting, code exec, install-time behavior) are present.
- `utils/ens/avatar/utils.ts` (medium): No clear malicious backdoor or exfiltration code was found, but the file performs unvalidated network fetches and URL rewriting on attacker-influenceable ENS avatar URIs, which warrants caution (SSRF and potential XSS via SVG data URIs) depending on how callers use the results.
- `utils/rpc/http.ts` (medium): This HTTP RPC client is not overtly malicious, but its extensible design (URL override via onRequest, injectable fetchFn, unvalidated headers) creates meaningful SSRF and data-exfiltration risks if used with untrusted configuration.
- `utils/uid.ts` (medium): No malicious behavior detected, but the uid() helper relies on non-cryptographic Math.random(), making it unsafe for security-sensitive identifier generation.
- `_cjs/account-abstraction/accounts/createWebAuthnCredential.js` (safe): The code is a straightforward wrapper around WebAuthn credential creation with no malicious patterns detected.
- `_cjs/account-abstraction/accounts/implementations/toCoinbaseSmartAccount.js` (safe): No malicious patterns detected; the code implements Coinbase Smart Account functionality using standard cryptographic operations without any suspicious behavior.
- `_cjs/account-abstraction/accounts/implementations/toSimple7702SmartAccount.js` (safe): No malicious patterns detected; the code implements an Ethereum account abstraction smart account factory with no exfiltration, obfuscation, or dangerous operations.
- `_cjs/account-abstraction/accounts/implementations/toSoladySmartAccount.js` (safe): The code is a standard ERC-4337 smart account implementation for Solady accounts, with no malicious patterns detected.
- `_cjs/account-abstraction/accounts/toSmartAccount.js` (safe): No malicious patterns detected; the code implements a smart account abstraction utility with standard blockchain interactions and no suspicious behavior.
- `_cjs/account-abstraction/accounts/toWebAuthnAccount.js` (safe): No malicious patterns detected; the file implements a WebAuthn account abstraction with no exfiltration, obfuscation, or suspicious behavior.
- `_cjs/account-abstraction/accounts/types.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/actions/bundler/estimateUserOperationGas.js` (safe): This file is a standard account abstraction module for estimating user operation gas via RPC; it contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, process spawning, or install-time hooks.
- `_cjs/account-abstraction/actions/bundler/getSupportedEntryPoints.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/actions/bundler/getUserOperation.js` (safe): No malicious patterns detected; the code performs a standard JSON-RPC request to fetch user operation data and formats the response.
- `_cjs/account-abstraction/actions/bundler/getUserOperationReceipt.js` (safe): The code performs a standard JSON-RPC request to fetch a user operation receipt and formats the result; no malicious patterns detected.
- `_cjs/account-abstraction/actions/bundler/prepareUserOperation.js` (safe): No malicious patterns detected in the prepareUserOperation action; it is a legitimate ERC-4337 bundler utility that builds UserOperation requests using existing account/client methods without exfiltration, eval, shell access, or credential harvesting.
- `_cjs/account-abstraction/actions/bundler/sendUserOperation.js` (safe): The code is a standard user operation sender for an account abstraction library; it shows no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning.
- `_cjs/account-abstraction/actions/bundler/waitForUserOperationReceipt.js` (safe): No malicious patterns detected; the code is a standard polling utility for waiting on blockchain user operation receipts.
- `_cjs/account-abstraction/actions/paymaster/getPaymasterData.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/actions/paymaster/getPaymasterStubData.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/clients/createBundlerClient.js` (safe): No malicious patterns detected; the code is a straightforward factory for creating a bundler client with standard imports and no suspicious behavior.
- `_cjs/account-abstraction/clients/createPaymasterClient.js` (safe): No malicious patterns detected; the code is a standard client factory for a paymaster client in an account abstraction library.
- `_cjs/account-abstraction/clients/decorators/bundler.js` (safe): No malicious patterns detected; the file only aggregates user operation actions and delegates to trusted internal modules without suspicious behavior.
- `_cjs/account-abstraction/clients/decorators/paymaster.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/constants/abis.js` (safe): No malicious patterns detected; the file only exports static Ethereum EntryPoint ABI definitions as plain data structures.
- `_cjs/account-abstraction/constants/address.js` (safe): The file only exports three hardcoded Ethereum EntryPoint contract addresses with no executable logic or malicious patterns.
- `_cjs/account-abstraction/errors/bundler.js` (safe): This file only defines error classes for bundler/account-abstraction errors, with no network, filesystem, process, or dynamic code execution behavior.
- `_cjs/account-abstraction/errors/userOperation.js` (safe): No malicious patterns detected; the file contains only error class definitions for user operation handling with no network, filesystem, process, or dynamic execution behavior.
- `_cjs/account-abstraction/index.js` (safe): No malicious patterns detected; the file only re-exports exports from internal modules and contains no executable logic, network activity, or obfuscation.
- `_cjs/account-abstraction/types/account.js` (safe): No malicious patterns detected in the provided file.
- `_cjs/account-abstraction/types/entryPointVersion.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/types/rpc.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/types/userOperation.js` (safe): The file contains only TypeScript compression boilerplate for a type declaration module, with no executable code or malicious patterns.
- `_cjs/account-abstraction/utils/errors/getBundlerError.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/utils/errors/getUserOperationError.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/utils/formatters/userOperation.js` (safe): No malicious patterns detected; the code only performs deterministic BigInt conversion for user operation parameters.
- `_cjs/account-abstraction/utils/formatters/userOperationGas.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/account-abstraction/utils/formatters/userOperationReceipt.js` (safe): No malicious patterns detected; the code performs straightforward formatting of user operation receipt data without any exfiltration, obfuscation, or dynamic execution.
- `_cjs/account-abstraction/utils/formatters/userOperationRequest.js` (safe): No malicious patterns detected; the code performs pure data formatting for Ethereum user operations without any network, filesystem, or dynamic execution activities.
- `_cjs/account-abstraction/utils/userOperation/getInitCode.js` (safe): No malicious patterns detected; the code performs deterministic data concatenation for Ethereum account abstraction init code without network, filesystem, or dynamic execution behavior.
- `_cjs/account-abstraction/utils/userOperation/getUserOperationHash.js` (safe): No malicious patterns detected; code performs standard ERC-4337 userOperation hash computation with no network, file, or process manipulation.
- `_cjs/account-abstraction/utils/userOperation/getUserOperationTypedData.js` (safe): No malicious patterns detected; the code constructs EIP-712 typed data for ERC-4337 PackedUserOperation using only local imports and standard object manipulation.
- `_cjs/account-abstraction/utils/userOperation/toPackedUserOperation.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/utils/userOperation/toUserOperation.js` (safe): No malicious patterns detected
- `_cjs/accounts/generateMnemonic.js` (safe): No malicious patterns detected
- `_cjs/accounts/generatePrivateKey.js` (safe): No malicious patterns detected; the code uses the reputable @noble/curves library to generate a secp256k1 private key and encodes it to hex.
- `_cjs/accounts/hdKeyToAccount.js` (safe): No malicious patterns detected; the code is a standard HD key to account conversion utility with no exfiltration, obfuscation, network, or process execution.
- `_cjs/accounts/index.js` (safe): No malicious patterns detected; the file is a standard re-export barrel for Ethereum account and signing utilities.
- `_cjs/accounts/mnemonicToAccount.js` (safe): No malicious patterns detected
- `_cjs/accounts/privateKeyToAccount.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic account creation module using standard imports and no suspicious behavior.
- `_cjs/accounts/toAccount.js` (safe): No malicious patterns detected; the file is a straightforward utility for normalizing Ethereum account objects with address validation and no external I/O or dynamic code execution.
- `_cjs/accounts/types.js` (safe): No malicious patterns detected
- `_cjs/accounts/utils/parseAccount.js` (safe): No malicious patterns detected
- `_cjs/accounts/utils/privateKeyToAddress.js` (safe): No malicious patterns detected; the code performs standard secp256k1 public key derivation and address computation without exfiltration, obfuscation, or side effects.
- `_cjs/accounts/utils/publicKeyToAddress.js` (safe): No malicious patterns detected; the code performs a standard Ethereum public key to address conversion using keccak256 and checksum formatting.
- `_cjs/accounts/utils/sign.js` (safe): No malicious patterns detected; the code performs standard ECDSA signing with optional user-controlled extra entropy and does not exfiltrate data, execute dynamic code, or access sensitive files.
- `_cjs/accounts/utils/signAuthorization.js` (safe): The code is a straightforward cryptographic signing utility with no malicious patterns, exfiltration, dynamic execution, or suspicious behavior.
- `_cjs/accounts/utils/signMessage.js` (safe): No malicious patterns detected; the file only implements cryptographic message signing using local utility imports.
- `_cjs/accounts/utils/signTransaction.js` (safe): No malicious patterns detected; the code is a standard Ethereum transaction signing utility using keccak256 and a local signing function with no exfiltration, obfuscation, or suspicious behavior.
- `_cjs/accounts/utils/signTypedData.js` (safe): No malicious patterns detected; the code is a straightforward typed-data signing utility with no exfiltration, obfuscation, network, filesystem, or process-spawning behavior.
- `_cjs/accounts/wordlists.js` (safe): No malicious patterns detected
- `_cjs/actions/ens/getEnsAddress.js` (safe): No malicious patterns detected; the code implements an ENS address resolution action using standard contract reads and ABI encoding/decoding without exfiltration, obfuscation, or dynamic execution.
- `_cjs/actions/ens/getEnsAvatar.js` (safe): No malicious patterns detected
- `_cjs/actions/ens/getEnsName.js` (safe): No malicious patterns detected in getEnsName.js; it implements standard ENS name resolution via readContract with no exfiltration, obfuscation, or unauthorized system access.
- `_cjs/actions/ens/getEnsResolver.js` (safe): This is a standard ENS resolver utility function with no malicious patterns, network exfiltration, or suspicious behavior detected.
- `_cjs/actions/ens/getEnsText.js` (safe): No malicious patterns detected; the code is a straightforward ENS text record retrieval utility using standard imports and contract calls.
- `_cjs/actions/getContract.js` (safe): No malicious patterns detected; the file is a standard viem-style contract interaction helper with expected dynamic ABI method resolution and no data exfiltration, credential harvesting, obfuscation, or process execution.
- `_cjs/actions/index.js` (safe): This is a standard barrel file re-exporting viem action modules with no malicious patterns, dynamic code execution, or suspicious behavior.
- `_cjs/actions/public/call.js` (safe): No malicious patterns detected
- `_cjs/actions/public/createAccessList.js` (safe): No malicious patterns detected
- `_cjs/actions/public/createBlockFilter.js` (safe): No malicious patterns detected; the code performs a standard Ethereum JSON-RPC call to create a block filter with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `_cjs/actions/public/createContractEventFilter.js` (safe): No malicious patterns detected; the code is a standard Ethereum contract event filter creation function from the viem library.
- `_cjs/actions/public/createEventFilter.js` (safe): No malicious patterns detected
- `_cjs/actions/public/createPendingTransactionFilter.js` (safe): No malicious patterns detected; the code is a standard Ethereum JSON-RPC client method for creating a pending transaction filter.
- `_cjs/actions/public/estimateContractGas.js` (safe): No malicious patterns detected; the code is a standard library function for estimating contract gas in a blockchain client.
- `_cjs/actions/public/estimateFeesPerGas.js` (safe): No malicious patterns detected; the file contains legitimate Ethereum fee estimation logic using standard viem library imports and no suspicious behavior.
- `_cjs/actions/public/estimateGas.js` (safe): This is a legitimate Ethereum gas estimation utility (likely from viem) with no malicious patterns, exfiltration, or suspicious behavior detected.
- `_cjs/actions/public/estimateMaxPriorityFeePerGas.js` (safe): No malicious patterns detected; the code appears to be a legitimate library function for estimating Ethereum transaction fees.
- `_cjs/actions/public/fillTransaction.js` (safe): No malicious patterns detected; the code is a legitimate transaction-filling utility with standard client JSON-RPC requests and no suspicious behavior.
- `_cjs/actions/public/getBalance.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getBlobBaseFee.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getBlock.js` (safe): This file implements a standard Ethereum JSON-RPC block retrieval utility with no malicious patterns, external data exfiltration, dynamic code execution, or install-time behavior.
- `_cjs/actions/public/getBlockNumber.js` (safe): No malicious patterns detected; the code is a straightforward Ethereum JSON-RPC wrapper that caches block numbers with no exfiltration, credential access, obfuscation, or process spawning.
- `_cjs/actions/public/getBlockTransactionCount.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getChainId.js` (safe): No malicious patterns detected; the file contains a standard Ethereum JSON-RPC call to retrieve the chain ID.
- `_cjs/actions/public/getCode.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getContractEvents.js` (safe): No malicious patterns detected; the code is a standard Ethereum contract event retrieval utility with no exfiltration, obfuscation, or dynamic execution.
- `_cjs/actions/public/getEip712Domain.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getFeeHistory.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getFilterChanges.js` (safe): No malicious patterns detected; the code performs legitimate Ethereum JSON-RPC filter change retrieval and log parsing.
- `_cjs/actions/public/getFilterLogs.js` (safe): No malicious patterns detected; the code is a straightforward Ethereum filter logs retrieval and parsing utility.
- `_cjs/actions/public/getGasPrice.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getLogs.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getProof.js` (safe): No malicious patterns detected; the code is a standard Ethereum JSON-RPC getProof implementation with no exfiltration, obfuscation, or suspicious behavior.
- `_cjs/actions/public/getStorageAt.js` (safe): No malicious patterns detected; the file is a straightforward viem library wrapper that calls eth_getStorageAt via the provided client.
- `_cjs/actions/public/getTransaction.js` (safe): No malicious patterns detected; the file is a standard Ethereum JSON-RPC client utility for fetching transactions.
- `_cjs/actions/public/getTransactionConfirmations.js` (safe): No malicious patterns detected; the code is a benign utility for calculating transaction confirmations using standard Ethereum client actions.
- `_cjs/actions/public/getTransactionCount.js` (safe): No malicious patterns detected; the code is a standard Ethereum JSON-RPC client helper for fetching transaction counts.
- `_cjs/actions/public/getTransactionReceipt.js` (safe): No malicious patterns detected; the code is a standard ethers-style RPC helper for fetching transaction receipts.
- `_cjs/actions/public/multicall.js` (safe): No malicious patterns detected in the multicall.js file; it appears to be legitimate Ethereum multicall contract interaction logic.
- `_cjs/actions/public/readContract.js` (safe): No malicious patterns detected; the file is a standard viem readContract utility with no exfiltration, obfuscation, dynamic execution, or suspicious I/O.
- `_cjs/actions/public/simulateBlocks.js` (safe): The file is a legitimate Ethereum JSON-RPC simulation utility with no malicious patterns, no external data exfiltration, no dynamic code execution, and no install-time or filesystem abuse.
- `_cjs/actions/public/simulateCalls.js` (safe): No malicious patterns detected; the code performs Ethereum call simulation with standard library imports and embedded contract bytecode, without data exfiltration, obfuscation, or execution of external commands.
- `_cjs/actions/public/simulateContract.js` (safe): No malicious patterns detected; the code is a standard Ethereum contract simulation utility with no external data transmission, credential access, dynamic code execution, or other suspicious behavior.
- `_cjs/actions/public/uninstallFilter.js` (safe): No malicious patterns detected; the file is a simple, legitimate Ethereum JSON-RPC helper for uninstalling a filter.
- `_cjs/actions/public/verifyHash.js` (safe): No malicious patterns detected; the code implements standard Ethereum signature verification (ERC-6492, ERC-8010, ERC-1271) without any exfiltration, obfuscation, or system-level abuse.
- `_cjs/actions/public/verifyMessage.js` (safe): No malicious patterns detected; the file contains a straightforward Ethereum message verification action with no exfiltration, obfuscation, or process/network side effects.
- `_cjs/actions/public/verifyTypedData.js` (safe): No malicious patterns detected; the code is a straightforward wrapper for verifying typed data signatures using internal utility functions.
- `_cjs/actions/public/waitForTransactionReceipt.js` (safe): The code is a legitimate implementation of an Ethereum transaction receipt waiting utility with no malicious patterns detected
- `_cjs/actions/public/watchBlockNumber.js` (safe): No malicious patterns detected; the code is a legitimate blockchain block number watcher implementation from viem.
- `_cjs/actions/public/watchBlocks.js` (safe): This is a legitimate viem library module for watching blockchain blocks; no malicious patterns, data exfiltration, obfuscation, or process spawning were detected.
- `_cjs/actions/public/watchContractEvent.js` (safe): No malicious patterns detected; the code is a standard viem library function for watching contract events via polling or WebSocket subscription.
- `_cjs/actions/public/watchEvent.js` (safe): No malicious patterns detected; the file implements a standard event-watching utility for Ethereum JSON-RPC clients with no data exfiltration, credential harvesting, obfuscation, or process spawning.
- `_cjs/actions/public/watchPendingTransactions.js` (safe): No malicious patterns detected; the code is a standard viem library utility for watching pending blockchain transactions via polling or websocket subscription.
- `_cjs/actions/siwe/verifySiweMessage.js` (safe): No malicious patterns detected; the code performs standard SIWE message verification using local utility functions without any exfiltration, obfuscation, or suspicious behavior.
- `_cjs/actions/wallet/addChain.js` (safe): No malicious patterns detected; the code is a straightforward wrapper for the EIP-3085 wallet_addEthereumChain RPC call.
- `_cjs/actions/wallet/deployContract.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/getAddresses.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/getCallsStatus.js` (safe): This file contains legitimate viem library code for checking Ethereum transaction call status via JSON-RPC, with no malicious patterns detected.
- `_cjs/actions/wallet/getCapabilities.js` (safe): No malicious patterns detected; the code implements a standard wallet capability query using an RPC call with no suspicious behavior.
- `_cjs/actions/wallet/getPermissions.js` (safe): No malicious patterns detected; the file is a straightforward wrapper for the wallet_getPermissions RPC method with no suspicious behavior.
- `_cjs/actions/wallet/prepareAuthorization.js` (safe): No malicious patterns detected; the file implements EIP-7702 authorization preparation using standard blockchain SDK utilities without any exfiltration, obfuscation, or suspicious behavior.
- `_cjs/actions/wallet/prepareTransactionRequest.js` (safe): No malicious patterns detected; this is a legitimate viem library file for preparing Ethereum transaction requests with no signs of data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `_cjs/actions/wallet/requestAddresses.js` (safe): No malicious patterns detected; the code simply requests Ethereum addresses from a client and normalizes them.
- `_cjs/actions/wallet/requestPermissions.js` (safe): No malicious patterns detected; code is a straightforward wrapper for a wallet permission request RPC call.
- `_cjs/actions/wallet/sendCalls.js` (safe): No malicious patterns detected; the code implements a standard EIP-5792 wallet_sendCalls with fallback to eth_sendTransaction and contains no exfiltration, obfuscation, or other suspicious behavior.
- `_cjs/actions/wallet/sendCallsSync.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/sendRawTransaction.js` (safe): The code is a simple wrapper for sending raw Ethereum transactions via a client request, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `_cjs/actions/wallet/sendRawTransactionSync.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/sendTransaction.js` (safe): No malicious patterns detected; the code implements a standard viem wallet transaction action with proper validation and error handling.
- `_cjs/actions/wallet/sendTransactionSync.js` (safe): No malicious patterns detected; the code implements a standard viem-style wallet transaction action with no exfiltration, credential harvesting, dynamic code execution, or process spawning.
- `_cjs/actions/wallet/showCallsStatus.js` (safe): No malicious patterns detected; the file only wraps a wallet_showCallsStatus RPC call with no exfiltration, obfuscation, or system-level operations.
- `_cjs/actions/wallet/signAuthorization.js` (safe): No malicious patterns detected; the code is a standard EIP-7702 authorization signing action with no data exfiltration, credential harvesting, or dynamic code execution.
- `_cjs/actions/wallet/signMessage.js` (safe): No malicious patterns detected; the code is a standard wallet signMessage action that delegates signing and makes a single RPC request without data exfiltration, obfuscation, or process execution.
- `_cjs/actions/wallet/signTransaction.js` (safe): This is a standard wallet transaction signing utility from viem with no malicious patterns, external data exfiltration, or credential harvesting.
- `_cjs/actions/wallet/signTypedData.js` (safe): No malicious patterns detected; the code is a standard Ethereum EIP-712 typed data signing utility with no network exfiltration, credential harvesting, obfuscation, or filesystem/process manipulation.
- `_cjs/actions/wallet/switchChain.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/waitForCallsStatus.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/watchAsset.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/writeContract.js` (safe): No malicious patterns detected; the code is a standard viem library function for writing to smart contracts.
- `_cjs/actions/wallet/writeContractSync.js` (safe): No malicious patterns detected; the file is a straightforward module wrapping internal writeContract and sendTransactionSync functions.
- `_cjs/celo/chainConfig.js` (safe): No malicious patterns detected; the file only imports local modules and exports a static object configuration.
- `_cjs/celo/fees.js` (safe): No malicious patterns detected
- `_cjs/celo/formatters.js` (safe): No malicious patterns detected; the file contains only standard Celo blockchain transaction/block formatters with no network, filesystem, process, or dynamic execution activity.
- `_cjs/celo/index.js` (safe): No malicious patterns detected; this is a simple barrel index file re-exporting chainConfig, parseTransaction, and serializeTransaction with no runtime side effects or suspicious behavior.
- `_cjs/celo/parsers.js` (safe): No malicious patterns detected; the code is a legitimate Celo transaction parser with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `_cjs/celo/serializers.js` (safe): No malicious patterns detected; the code implements CIP-42/64 transaction serialization and validation with no data exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
- `_cjs/celo/types.js` (safe): No malicious patterns detected
- `_cjs/celo/utils.js` (safe): No malicious patterns detected; the code contains only simple utility functions for value checks and transaction type detection with no network, filesystem, or process activity.
- `_cjs/chains/definitions/0g.js` (safe): No malicious patterns detected; the file only defines a blockchain network configuration using a standard defineChain utility.
- `_cjs/chains/definitions/0gGalileoTestnet.js` (safe): No malicious patterns detected; the file only defines a blockchain chain configuration with static RPC URLs and no executable behavior.
- `_cjs/chains/definitions/0gMainnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/0gTestnet.js` (safe): No malicious patterns detected; the file only defines a static blockchain testnet configuration using standard library utilities.
- `_cjs/chains/definitions/5ireChain.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/abey.js` (safe): No malicious patterns detected; the file only defines a blockchain network configuration using a local utility import.
- `_cjs/chains/definitions/abstract.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/abstractTestnet.js` (safe): This file is a straightforward chain definition for a blockchain testnet, containing only static configuration data with no executable or suspicious code.
- `_cjs/chains/definitions/acala.js` (safe): No malicious patterns detected; the file is a standard chain definition module with static configuration data only.
- `_cjs/chains/definitions/acria.js` (safe): No malicious patterns detected; the file only defines chain metadata (id, name, RPC URL, explorer) with no suspicious behavior.
- `_cjs/chains/definitions/adf.js` (safe): No malicious patterns detected; the file only defines a blockchain chain configuration with static metadata and no executable or network-triggering code.
- `_cjs/chains/definitions/agungTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/aioz.js` (safe): No malicious patterns detected; the file is a standard chain definition for AIOZ Network with no obfuscation, network requests, or system access.
- `_cjs/chains/definitions/alephZero.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/alephZeroTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/alienX.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/alienXHalTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/ancient8.js` (safe): No malicious patterns detected; the file is a standard chain configuration definition with no executable or exfiltration behavior.
- `_cjs/chains/definitions/ancient8Sepolia.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/anvil.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/apeChain.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/apexTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/arbitrum.js` (safe): Static chain definition for Arbitrum One containing only configuration constants (RPC URL, block explorer, multicall address) with no dynamic code execution, network requests, file system access, or malicious patterns.
- `_cjs/chains/definitions/arbitrumGoerli.js` (safe): No malicious patterns detected; the file is a standard chain definition for Arbitrum Goerli with no dynamic execution, network calls, or credential harvesting.
- `_cjs/chains/definitions/arbitrumNova.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/arbitrumSepolia.js` (safe): No malicious patterns detected; the file is a standard chain definition for Arbitrum Sepolia with no risky behavior.
- `_cjs/chains/definitions/arcTestnet.js` (safe): No malicious patterns detected; the file is a standard chain definition exporting RPC URLs and contract addresses.
- `_cjs/chains/definitions/arenaz.js` (safe): No malicious patterns detected; the file only defines and exports a blockchain chain configuration with static URLs and no executable or suspicious behavior.
- `_cjs/chains/definitions/areonNetwork.js` (safe): No malicious patterns detected in the chain definition file; it only contains standard blockchain network configuration.
- `_cjs/chains/definitions/areonNetworkTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/areum.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/artelaTestnet.js` (safe): No malicious patterns detected; the file is a standard chain definition configuration for Artela Testnet.
- `_cjs/chains/definitions/arthera.js` (safe): This file is a standard chain definition for the Arthera network and contains no malicious patterns or security concerns.
- `_cjs/chains/definitions/artheraTestnet.js` (safe): No malicious patterns detected; the file is a simple, static chain definition for the Arthera Testnet.
- `_cjs/chains/definitions/assetChain.js` (safe): The file contains only a static chain definition with hardcoded RPC and explorer URLs and no malicious patterns or dynamic behavior.
- `_cjs/chains/definitions/assetChainTestnet.js` (safe): No malicious patterns detected; the file only defines a blockchain chain configuration with static URLs and contract addresses.
- `_cjs/chains/definitions/astar.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/astarZkEVM.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/astarZkyoto.js` (safe): This file only defines a blockchain chain configuration object with a static RPC URL and multicall contract address, and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `_cjs/chains/definitions/atletaOlympia.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/aurora.js` (safe): No malicious patterns detected; the file is a standard chain definition for Aurora with no network, filesystem, process, or obfuscated code.
- `_cjs/chains/definitions/auroraTestnet.js` (safe): No malicious patterns detected

## Version ranges

None of the 2 scanned versions of viem are flagged high or critical. The latest scanned version, 2.47.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.47.0 (`2.47.0`): not scanned
- 2.23.2 – 2.41.2 (`>=2.23.2 <=2.41.2`): medium (Resource exhaustion / unbounded recursion +4 more)

## Scanned versions

- [2.41.2](https://security.togoder.click/npm/viem@2.41.2): medium, 2026-10-04T16:54:47.000Z
- [2.23.2](https://security.togoder.click/npm/viem@2.23.2): medium, 2026-10-04T16:54:42.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
